Penalties: three tiers and a calculator mindset
Lesson 4 of 6 in Governance, Enforcement, Penalties, and Sandboxes.
Article 99 builds a three-tier fine structure, and the design principle is familiar from the GDPR: caps expressed as a fixed sum or a percentage of total worldwide annual turnover, whichever is higher — so no company is too big for the fine to hurt. Member States set the actual penalty rules and their authorities impose them (notifying the Commission of their regimes); the Act fixes the ceilings and the aggravating/mitigating factors: nature, gravity and duration; intent or negligence; corrective actions taken; prior fines; size and market share; financial benefit gained or losses avoided; degree of cooperation.
One deliberate inversion protects small players: for SMEs and startups, each fine is capped at the lower of the percentage or the fixed amount — the exact opposite of the whichever-is-higher rule that applies to everyone else.
| Tier | Ceiling | What triggers it | Notes |
|---|---|---|---|
Tier 1 — prohibited practices | €35M or 7% of worldwide annual turnover, whichever is higher | Non-compliance with the Article 5 prohibitions — social scoring, untargeted face scraping, and the rest | The highest percentage cap in EU digital law short of the DMA’s 10% — above GDPR’s 4% |
Tier 2 — operator and notified-body obligations | €15M or 3%, whichever is higher | Breach of most substantive duties: provider obligations (Art 16), authorised representatives (22), importers (23), distributors (24), deployers (26), notified bodies (Arts 31, 33(1), (3), (4), 34), and Art 50 transparency duties | The everyday tier — where Annex IV gaps, missing oversight, and skipped registrations land |
Tier 3 — misleading information | €7.5M or 1%, whichever is higher | Supplying incorrect, incomplete, or misleading information to notified bodies or competent authorities | Lying about compliance is fined separately from failing to comply |
SMEs and startups | Each ceiling applies at the lower of the amount or percentage | All of the above tiers | The inverted rule — proportionality for small operators (Art 99(6)) |
Union institutions (Art 100) | Up to €1.5M (prohibited practices) / €750k (other obligations) | AI Act breaches by EU institutions, bodies, and agencies | Imposed by the EDPS — the Union polices itself on a smaller scale |
GPAI providers (Art 101) | Up to €15M or 3%, whichever is higher | Intentional or negligent infringement of GPAI obligations, or failure to comply with document requests, evaluations, or access demands | Imposed by the Commission — the only fines in the Act levied centrally |
Interactive sorting exercise: Fine calculator triage: drop each violation into the penalty lane it belongs to.
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.